Description
ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration
of affected versions, exposes its data and configuration endpoint
without any authentication and permissive CORS on every response. An
unauthenticated attacker with network access can read live process
values and server configuration.
Published: 2026-07-31
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises because ANDRITZ HIPASE-250 exposes data and configuration endpoints without requiring authentication and applies a permissive Cross‑Origin Resource Sharing policy to every response. This flaw allows an attacker who can reach the device over the network to read live process values and the server’s configuration settings. The impact is a breach of confidentiality, potentially revealing sensitive production data and operational details that could aid further attacks or competitive intelligence.

Affected Systems

This flaw affects ANDRITZ HIPASE‑250, which was previously known as 250 SCALA, when deployed in its default configuration. The vulnerability applies to any affected version using the default settings; no specific software revision is cited in the advisory.

Risk and Exploitability

The CVSS score of 7.5 indicates a high‑severity risk, while the EPSS score of less than 1% suggests that exploitation is rare at present and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, an attacker that can reach the device, such as one on the same industrial network or with compromised credentials on the network, can exploit the flaw simply by issuing HTTP requests to the exposed endpoints. The lack of authentication and overly permissive CORS make the attack trivial once network access is achieved, underscoring the need for immediate remedial action.

Generated by OpenCVE AI on August 3, 2026 at 09:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware or service pack that requires authentication for data and configuration endpoints.
  • If an updated firmware is unavailable, restrict access to the exposed endpoints by placing the device behind a firewall or network segmentation so that only trusted internal networks can reach them.
  • Configure the device’s CORS policy to permit requests only from explicitly trusted domains, eliminating the permissive behaviour.

Generated by OpenCVE AI on August 3, 2026 at 09:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://www.andritz.com/ cve-icon cve-icon
History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Andritz
Andritz 250 Scala
Andritz hipase-250
Vendors & Products Andritz
Andritz 250 Scala
Andritz hipase-250

Fri, 31 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Description ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any authentication and permissive CORS on every response. An unauthenticated attacker with network access can read live process values and server configuration.
Title Missing authentication and permissive CORS policy
Weaknesses CWE-306
CWE-942
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Andritz 250 Scala Hipase-250
cve-icon MITRE

Status: PUBLISHED

Assigner: CyberDanube

Published:

Updated: 2026-07-31T16:34:44.010Z

Reserved: 2026-07-21T20:33:52.962Z

Link: CVE-2026-65310

cve-icon Vulnrichment

Updated: 2026-07-31T16:34:32.086Z

cve-icon NVD

Status : Received

Published: 2026-07-31T09:16:58.447

Modified: 2026-07-31T17:16:34.750

Link: CVE-2026-65310

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T10:00:12Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function

  • CWE-942

    Permissive Cross-domain Security Policy with Untrusted Domains